The critical RCE vulnerability CVE-2026-60004 in Gitea is being actively exploited, according to an urgent advisory issued by the US Cybersecurity and Infrastructure Security Agency ( CISA ). The vulnerability, with a CVSS score of 9.8 , allows an attacker with simple write permissions to a repository to execute arbitrary shell commands as the Gitea OS user . The situation is particularly concerning as confirmed exploits have already been documented online, with attackers deploying cryptominer payloads on vulnerable systems.

CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) on August 25, 2026, confirming that the threat is not theoretical but real. The vulnerability affects all Gitea from 1.17 to 1.27.0, while the fix was released with version 1.27.1 in late July 2026. Security researcher Shai Rod (aka NightRang3r) is credited with discovering and reporting the issue to the Gitea development team.
Gitea is a popular, lightweight self-hosted Git, widely used by developers, software development teams, and organizations that want to keep their code off of large cloud platforms. It is precisely this widespread use in self-hosted environments — often without strict security monitoring — that makes the vulnerability particularly dangerous for thousands of installations worldwide.
See also: CVE-2026-60236: Critical RCE in Oracle Coherence (CVSS 9.8) – what to do now
How the Gitea vulnerability CVE-2026-60004 works
The technical issue is in the way Gitea handles applying patches via the POST endpoint /api/v1/repos/{owner}/{repo}/diffpatch. According to Gitea's official announcement, "the diffpatch endpoint can be misused to install and execute a Git hook from content controlled by the repository." The dangerous interaction occurs between the diffpatch stream, a temporary bare clone, and Git's conflict resolution behavior, which can write a malicious hook to the repository's hooks directory.
The most worrying aspect of the vulnerability is that it doesn’t require administrator privileges. All it takes is an account with write permissions to a repository. And here’s the crucial detail: Gitea allows new users to freely register by default. This means that an external attacker could create an account, create a repository, gain the necessary write permissions, and then activate the exploit — without needing any pre-existing credentials. CISA describes the vulnerability as a “code injection vulnerability that allows an attacker with write permissions to a repository to send a malicious patch to the diffpatch API endpoint, install an executable Git hook, and execute shell commands as the Gitea service account.”

Settings that make a Gitea installation particularly vulnerable include: DISABLE_REGISTRATION = false (free user registration), REGISTER_EMAIL_CONFIRM = false (no email confirmation), ENABLE_OPENID_SIGNUP = true (registration via OpenID), and REQUIRE_SIGNIN_VIEW = false (no login required to view pages or use APIs). This combination of default settings creates an ideal environment for exploitation.
Real-life incident: Gitea RCE for cryptominer development
A real-life case of RCE exploitation was revealed in an analysis published by developer Andrey (known as @Causelof) on the Russian blogging platform Habr. His Gitea installation was targeted by an unknown threat actor who used CVE-2026-60004 to deploy a dropper with cryptocurrency miner. The incident was revealed when hosting provider HOSTKEY sent a notification that the virtual server was using more than 70% of its processing power for an extended period of time, violating its terms of service.
See also: CVE-2026-56163: Critical EoP in Azure Kubernetes Service (AKS) – Mitigated by Microsoft
The dropper script executed through the vulnerability followed a series of steps before deploying the final payload: it cleared the LD_PRELOAD and LD_LIBRARY_PATH, looked for processes with high CPU usage, attempted to terminate competing processes, retrieved the payload based on the system architecture, downloaded and executed it, and finally deleted the file after execution. The exact nature of the final payload remains unknown, as the user did not analyze its contents, however the sharp increase in CPU usage is consistent with a cryptojacking targeting vulnerable Gitea installations.
Protection from the Gitea vulnerability: Immediate steps
The most critical action for any organization using Gitea is to immediately upgrade to version 1.27.1 or later, which contains the official fix for CVE-2026-60004. In addition, administrators should review user registration settings and disable free registration if not necessary, while enabling email confirmation. Disabling ENABLE_OPENID_SIGNUP and enabling REQUIRE_SIGNIN_VIEW can also significantly reduce the attack surface.
Security teams should review logs for unusual activity on the diffpatch and suspicious filesystem changes related to hooks. If signs of exploitation are found, it is recommended to assume the system has been compromised and immediately rotate the credentials and tokens used by the Gitea service account. For organizations subject to federal or regulatory requirements, CISA has set a specific remediation deadline through the KEV catalog.

Additionally, it is recommended to conduct a complete inventory of all Gitea installations in the organization, with particular emphasis on those accessible from the internet. Reviewing repository permissions and removing unnecessary write permissions are also important risk mitigation measures.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Overall, the CVE-2026-60004 vulnerability is a prime example of how default security settings can turn a technical weakness into a critical threat. The ease of exploitation — which does not require pre-existing credentials — combined with the widespread use of Gitea in self-hosted environments makes immediate response imperative. According to The Hacker News, CISA did not disclose details about who is behind the attacks, but the inclusion in the KEV catalog is a clear signal that the exploit is real and active.
